2. Shortage of passby mode
When using a passby mode in LAN. Limited with the network topology, Active Wall can not deny UDP/ICMP/IGMP packets. Several filtering modules do not work. If the option [Enable active redirect on passby mode] is checked, Active Wall will start the function ARP spoofing, which will redirect all the data packets in LAN. It is recommended that the ARP spoofing function is used only in small-sized LAN, for the reason that this function does some impacts on performance of the whole network.

3. Delay of domain filtering module
When a computer in LAN tries to analyze a domain name, it will firstly search in local host DNS cache. If it can find the domain name, it will return at once. Or it will send a DNS query request. So a new policy on DNS filter module may not work at once on the monitored computers. After the local host DNS cache expires, the policy will work.